Managed XDR

copia-de-patch_etabs.v21.2.rar — malware analysis report

File info

Filename
copia-de-patch_etabs.v21.2.rar
File type
RAR archive data, v5
File size
2.7 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
481aa19e2a13548d5c07b8b23c153ecd2c269bd8
SHA256
98b964394f1252642413ade1a43b7b50ec3c552043244371a483c7ff2054714f
MD5
7828e499a4ed828c3b2f52ea7aa1d5a8

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_themida: Themida packer signatures detected
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.001 antivm_generic_video: Checks information about video adapters in registry, possibly for anti-virtualization
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_generic_video: Checks information about video adapters in registry, possibly for anti-virtualization

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
message_box: Displays a message
checktokenmembership: Checks user token with CheckTokenMembership call